Odyssey Academy
Attack Intelligence
Odyssey Academy was compromised in a ransomware attack attributed to interlock in February 2026. The organization, operating in the Education sector in United States, was added to the group's data leak site as part of an extortion campaign.
interlock operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Odyssey Academy is a free public charter school. This school educates and prepares children for adulthood, but a large amount of data has become publicly available due to the disrespectful and negligent attitude of its staff and administration. As a result, student and staff data and the school's records, including full financial reports and other confidential documentation, have been compromised.
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2026-20131, which may have been leveraged as initial access vectors or for lateral movement.